Skip to content

[Security] CVE-2022-42003 in jackson-databind 2.13.1 (CVSS 7.5) #152

Description

@bsmitches

Vulnerability Details

  • CVE: CVE-2022-42003
  • Severity: HIGH (CVSS 7.5)
  • Affected dependency: com.fasterxml.jackson.core:jackson-databind:2.13.1

Description

In FasterXML jackson-databind 2.13.1, there is a Denial of Service vulnerability via a large depth of nested objects when the UNWRAP_SINGLE_VALUE_ARRAYS feature is enabled. This can be exploited via crafted JSON input to cause excessive resource consumption.

Remediation

Upgrade jackson-databind to >= 2.13.4.2 or upgrade the Spring Boot parent which manages this transitively.


Created to demonstrate the SAST → Automation → Devin remediation pipeline

Metadata

Metadata

Assignees

No one assigned

    Labels

    securitySecurity vulnerability

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions